"Technique ID","Detection Available","Link","score" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0" "T1162","No","-","0" "T1078.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml","1" "T1588.001","No","-","0" "T1031","No","-","0" "T1103","No","-","0" "T1546.006","No","-","0" "T1100","No","-","0" "T1542.002","No","-","0" "T1055.011","No","-","0" "T1067","No","-","0" "T1547.013","No","-","0" "T1052.001","No","-","0" "T1048.002","No","-","0" "T1052","No","-","0" "T1209","No","-","0" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","5" "T1590","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","5" "T1505.002","No","-","0" "T1087.004","No","-","0" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml","7" "T1003.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml","7" "T1055.003","No","-","0" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","4" "T1484","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","4" "T1218.008","No","-","0" "T1033","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml","1" "T1578.004","No","-","0" "T1110.004","No","-","0" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","5" "T1574","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","5" "T1558.002","No","-","0" "T1494","No","-","0" "T1121","No","-","0" "T1037.003","No","-","0" "T1060","No","-","0" "T1058","No","-","0" "T1102.003","No","-","0" "T1584.001","No","-","0" "T1026","No","-","0" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml","9" "T1048","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml","9" "T1070.006","No","-","0" "T1223","No","-","0" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1039","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1061","No","-","0" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml","3" "T1112","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml","3" "T1562.006","No","-","0" "T1550.004","No","-","0" "T1038","No","-","0" "T1037.004","No","-","0" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","5" "T1027","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml","5" "T1564","No","-","2" "T1188","No","-","0" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml","44" "T1078","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml","44" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml","4" "T1204.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml","4" "T1006","No","-","0" "T1561.002","No","-","0" "T1070.003","No","-","0" "T1522","No","-","0" "T1557.002","No","-","0" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1134","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","4" "T1594","No","-","0" "T1574.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml","1" "T1037.005","No","-","0" "T1562.008","No","-","0" "T1056.004","No","-","0" "T1110.002","No","-","0" "T1505","No","-","2" "T1527","No","-","0" "T1065","No","-","0" "T1606","No","-","0" "T1075","No","-","0" "T1598","No","-","0" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","2" "T1564.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml","2" "T1020","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml","2" "T1174","No","-","0" "T1053.001","No","-","0" "T1610","No","-","0" "T1496","No","-","0" "T1055.008","No","-","0" "T1578","No","-","0" "T1584.002","No","-","0" "T1574.004","No","-","0" "T1547.004","No","-","0" "T1574.001","No","-","0" "T1170","No","-","0" "T1063","No","-","0" "T1583.002","No","-","0" "T1056.002","No","-","0" "T1502","No","-","0" "T1578.002","No","-","0" "T1134.004","No","-","0" "T1074.002","No","-","0" "T1037.002","No","-","0" "T1573.002","No","-","0" "T1555.003","No","-","0" "T1177","No","-","0" "T1480","No","-","0" "T1157","No","-","0" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml","3" "T1546.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml","3" "T1158","No","-","0" "T1200","No","-","0" "T1567.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_drive_share_in_external_email.yml","1" "T1003.006","No","-","0" "T1497","No","-","0" "T1137.004","No","-","0" "T1221","No","-","0" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","4" "T1105","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml","4" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml","2" "T1140","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml","2" "T1180","No","-","0" "T1195","No","-","0" "T1613","No","-","0" "T1124","No","-","0" "T1587.003","No","-","0" "T1190","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml","1" "T1175","No","-","0" "T1548.001","No","-","0" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml","2" "T1558.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml","2" "T1078.001","No","-","0" "T1601","No","-","0" "T1606.002","No","-","0" "T1564.007","No","-","0" "T1518","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1133","No","-","0" "T1592.001","No","-","0" "T1542.005","No","-","0" "T1003.008","No","-","0" "T1493","No","-","0" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml","12" "T1036","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml","12" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml","5" "T1047","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml","5" "T1574.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml","1" "T1566.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml","1" "T1499.003","No","-","0" "T1218.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml","1" "T1564.004","No","-","0" "T1153","No","-","0" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml","22" "T1562.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml","22" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml","9" "T1021","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","9" "T1148","No","-","0" "T1055.013","No","-","0" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml","2" "T1021.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml","2" "T1563.002","No","-","0" "T1027.004","No","-","0" "T1183","No","-","0" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml","10" "T1003.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml","10" "T1123","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1567.001","No","-","0" "T1204.001","No","-","0" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml","5" "T1560.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml","5" "T1008","No","-","0" "T1547.009","No","-","0" "T1055.012","No","-","0" "T1547.007","No","-","0" "T1546.009","No","-","0" "T1553.001","No","-","0" "T1491","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml","1" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml","2" "T1530","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml","2" "T1071","No","-","3" "T1574.005","No","-","0" "T1555.004","No","-","0" "T1567","No","-","1" "T1134.003","No","-","0" "T1599","No","-","0" "T1086","No","-","0" "T1546","No","-","9" "T1069.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","1" "T1088","No","-","0" "T1160","No","-","0" "T1492","No","-","0" "T1055.004","No","-","0" "T1027.003","No","-","0" "T1032","No","-","0" "T1021.006","No","-","0" "T1547.005","No","-","0" "T1589.002","No","-","0" "T1590.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1171","No","-","0" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml","16" "T1087","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml","16" "T1588.006","No","-","0" "T1214","No","-","0" "T1138","No","-","0" "T1036.004","No","-","0" "T1054","No","-","0" "T1137.003","No","-","0" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","2" "T1199","Yes","https://github.com/splunk/security_content/blob/develop/cloud/github_commit_changes_in_master.yml","2" "T1589.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","2" "T1554","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","2" "T1081","No","-","0" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml","2" "T1562.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml","2" "T1114","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml","5" "T1586","No","-","0" "T1497.002","No","-","0" "T1587.001","No","-","0" "T1584.006","No","-","0" "T1002","No","-","0" "T1565.003","No","-","0" "T1560","No","-","5" "T1070.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml","1" "T1016.001","No","-","0" "T1137","No","-","0" "T1202","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1195.002","No","-","0" "T1584.003","No","-","0" "T1201","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1547.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml","1" "T1574.007","No","-","0" "T1553.003","No","-","0" "T1590.006","No","-","0" "T1055.002","No","-","0" "T1503","No","-","0" "T1557","No","-","0" "T1598.003","No","-","0" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml","2" "T1547.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml","2" "T1208","No","-","0" "T1546.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml","1" "T1118","No","-","0" "T1583.005","No","-","0" "T1195.003","No","-","0" "T1556.002","No","-","0" "T1041","No","-","0" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","2" "T1106","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","2" "T1085","No","-","0" "T1043","No","-","0" "T1562.002","No","-","0" "T1568","No","-","0" "T1584","No","-","0" "T1558.004","No","-","0" "T1614","No","-","0" "T1203","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1090.002","No","-","0" "T1608.001","No","-","0" "T1584.005","No","-","0" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml","8" "T1482","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","8" "T1129","No","-","0" "T1037","No","-","0" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml","3" "T1127.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","3" "T1220","No","-","0" "T1073","No","-","0" "T1134.005","No","-","0" "T1552","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","1" "T1596.002","No","-","0" "T1144","No","-","0" "T1597.002","No","-","0" "T1585","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml","1" "T1591.001","No","-","0" "T1574.012","No","-","0" "T1559.001","No","-","0" "T1021.005","No","-","0" "T1550.003","No","-","0" "T1056.003","No","-","0" "T1134.002","No","-","0" "T1574.008","No","-","0" "T1010","No","-","0" "T1082","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml","1" "T1574.006","No","-","0" "T1592.003","No","-","0" "T1027.001","No","-","0" "T1565","No","-","0" "T1192","No","-","0" "T1102","No","-","0" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml","18" "T1055","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml","18" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml","3" "T1136.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml","3" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml","8" "T1489","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml","8" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml","14" "T1053","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","14" "T1215","No","-","0" "T1012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml","6" "T1070.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml","6" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml","2" "T1078.002","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml","2" "T1164","No","-","0" "T1036.002","No","-","0" "T1564.005","No","-","0" "T1066","No","-","0" "T1498.001","No","-","0" "T1571","No","-","0" "T1003.005","No","-","0" "T1562.003","No","-","0" "T1119","No","-","0" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml","4" "T1569.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml","4" "T1586.002","No","-","0" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1612","No","-","0" "T1536","No","-","0" "T1218.002","No","-","0" "T1090.001","No","-","0" "T1172","No","-","0" "T1090","No","-","0" "T1561","No","-","0" "T1059.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml","1" "T1562","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml","31" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml","3" "T1485","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml","3" "T1045","No","-","0" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml","6" "T1218.009","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml","6" "T1146","No","-","0" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml","7" "T1053.005","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml","7" "T1566.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml","1" "T1114.002","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml","1" "T1525","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml","1" "T1196","No","-","0" "T1071.003","No","-","0" "T1059.006","No","-","0" "T1001.003","No","-","0" "T1211","No","-","0" "T1587","No","-","0" "T1110.001","No","-","0" "T1137.006","No","-","0" "T1062","No","-","0" "T1024","No","-","0" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","2" "T1592.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1181","No","-","0" "T1173","No","-","0" "T1122","No","-","0" "T1091","No","-","0" "T1156","No","-","0" "T1574.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml","1" "T1595.001","No","-","0" "T1134.001","No","-","0" "T1560.003","No","-","0" "T1195.001","No","-","0" "T1597","No","-","0" "T1084","No","-","0" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml","30" "T1059","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml","30" "T1546.010","No","-","0" "T1205.001","No","-","0" "T1083","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","1" "T1608.003","No","-","0" "T1602.001","No","-","0" "T1564.006","No","-","0" "T1519","No","-","0" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml","6" "T1486","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml","6" "T1001.002","No","-","0" "T1055.005","No","-","0" "T1001","No","-","0" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml","14" "T1218.011","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml","14" "T1600.001","No","-","0" "T1165","No","-","0" "T1543.004","No","-","0" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml","5" "T1127","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","5" "T1497.003","No","-","0" "T1194","No","-","0" "T1004","No","-","0" "T1036.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","1" "T1555.002","No","-","0" "T1546.008","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml","1" "T1518.001","No","-","0" "T1037.001","No","-","0" "T1167","No","-","0" "T1056","No","-","0" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml","6" "T1136.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml","6" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml","3" "T1218.010","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml","3" "T1094","No","-","0" "T1216","No","-","0" "T1608","No","-","0" "T1077","No","-","0" "T1055.014","No","-","0" "T1539","No","-","0" "T1185","No","-","0" "T1149","No","-","0" "T1548.004","No","-","0" "T1590.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml","1" "T1480.001","No","-","0" "T1205","No","-","0" "T1548.003","No","-","0" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml","2" "T1550.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml","2" "T1547.003","No","-","0" "T1491.002","No","-","0" "T1590.002","No","-","0" "T1219","No","-","0" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml","7" "T1490","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml","7" "T1217","No","-","0" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1046","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1003.004","No","-","0" "T1042","No","-","0" "T1589.003","No","-","0" "T1484.001","No","-","0" "T1506","No","-","0" "T1072","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml","1" "T1005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml","1" "T1151","No","-","0" "T1098.003","No","-","0" "T1014","No","-","0" "T1155","No","-","0" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","16" "T1548","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml","16" "T1189","Yes","https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml","1" "T1166","No","-","0" "T1553.006","No","-","0" "T1101","No","-","0" "T1587.002","No","-","0" "T1552.004","No","-","0" "T1568.002","No","-","0" "T1137.002","No","-","0" "T1501","No","-","0" "T1543.001","No","-","0" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml","3" "T1197","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml","3" "T1514","No","-","0" "T1093","No","-","0" "T1602","No","-","0" "T1069","No","-","11" "T1027.002","No","-","0" "T1563","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1564.003","No","-","0" "T1218","No","-","39" "T1546.002","No","-","0" "T1491.001","No","-","0" "T1534","No","-","0" "T1568.003","No","-","0" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","6" "T1087.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","6" "T1059.002","No","-","0" "T1550","No","-","2" "T1553","No","-","1" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml","7" "T1592","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml","7" "T1109","No","-","0" "T1558.001","No","-","0" "T1595.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml","1" "T1079","No","-","0" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","10" "T1110","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml","10" "T1601.001","No","-","0" "T1587.004","No","-","0" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","12" "T1547","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","12" "T1018","No","-","0" "T1570","No","-","0" "T1546.007","No","-","0" "T1602.002","No","-","0" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml","38" "T1003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml","38" "T1117","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml","1" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml","12" "T1070","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml","12" "T1488","No","-","0" "T1013","No","-","0" "T1108","No","-","0" "T1055.009","No","-","0" "T1015","No","-","0" "T1504","No","-","0" "T1606.001","No","-","0" "T1593.001","No","-","0" "T1020.001","No","-","0" "T1589","No","-","1" "T1115","No","-","0" "T1159","No","-","0" "T1550.001","No","-","0" "T1586.001","No","-","0" "T1213","No","-","0" "T1556.003","No","-","0" "T1147","No","-","0" "T1552.002","No","-","0" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_suspicious_subject_with_attachment.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_suspicious_shared_file_name.yml","17" "T1566.001","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_email_with_known_abuse_web_service_link.yml","17" "T1169","No","-","0" "T1552.001","No","-","0" "T1583","No","-","0" "T1559","No","-","0" "T1588.005","No","-","0" "T1593","No","-","0" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml","7" "T1048.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml","7" "T1552.006","No","-","0" "T1096","No","-","0" "T1546.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml","1" "T1569.001","No","-","0" "T1487","No","-","0" "T1137.001","No","-","0" "T1578.001","No","-","0" "T1034","No","-","0" "T1143","No","-","0" "T1599.001","No","-","0" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml","2" "T1027.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml","2" "T1609","No","-","0" "T1555.001","No","-","0" "T1498.002","No","-","0" "T1497.001","No","-","0" "T1588.002","No","-","0" "T1137.005","No","-","0" "T1608.005","No","-","0" "T1198","No","-","0" "T1044","No","-","0" "T1529","No","-","0" "T1102.002","No","-","0" "T1608.004","No","-","0" "T1222.002","No","-","0" "T1113","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml","1" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml","2" "T1057","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml","2" "T1210","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml","1" "T1070.002","No","-","0" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml","4" "T1543.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml","4" "T1120","No","-","0" "T1142","No","-","0" "T1528","No","-","0" "T1023","No","-","0" "T1022","No","-","0" "T1585.001","No","-","0" "T1059.004","No","-","0" "T1578.003","No","-","0" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml","6" "T1547.012","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml","6" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_lfi.yml","2" "T1212","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_nginx_ingress_rfi.yml","2" "T1161","No","-","0" "T1090.003","No","-","0" "T1588","No","-","0" "T1184","No","-","0" "T1601.002","No","-","0" "T1222.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml","1" "T1053.007","No","-","0" "T1555.005","No","-","0" "T1053.004","No","-","0" "T1182","No","-","0" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml","4" "T1526","Yes","https://github.com/splunk/security_content/blob/develop/cloud/kubernetes_scanner_image_pulling.yml","4" "T1483","No","-","0" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml","8" "T1110.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml","8" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","6" "T1059.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml","6" "T1186","No","-","0" "T1193","No","-","0" "T1600.002","No","-","0" "T1074.001","No","-","0" "T1546.014","No","-","0" "T1102.001","No","-","0" "T1573.001","No","-","0" "T1191","No","-","0" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml","2" "T1070.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml","2" "T1074","No","-","0" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml","8" "T1535","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml","8" "T1089","No","-","0" "T1505.001","No","-","0" "T1552.003","No","-","0" "T1538","No","-","0" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml","5" "T1021.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml","5" "T1130","No","-","0" "T1003.007","No","-","0" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml","2" "T1546.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml","2" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1553.005","No","-","0" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","2" "T1207","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml","2" "T1505.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml","2" "T1583.003","No","-","0" "T1600","No","-","0" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/esentutl_sam_copy.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml","8" "T1003.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml","8" "T1542.004","No","-","0" "T1030","No","-","0" "T1216.001","No","-","0" "T1546.004","No","-","0" "T1055.001","No","-","0" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml","12" "T1204","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml","12" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml","2" "T1071.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml","2" "T1016","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml","1" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","3" "T1555","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml","3" "T1557.001","No","-","0" "T1573","No","-","0" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml","4" "T1218.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml","4" "T1059.008","No","-","0" "T1499.004","No","-","0" "T1163","No","-","0" "T1596.001","No","-","0" "T1071.002","No","-","0" "T1179","No","-","0" "T1591.003","No","-","0" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","4" "T1558","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","4" "T1484.002","No","-","0" "T1050","No","-","0" "T1132.002","No","-","0" "T1585.002","No","-","0" "T1011","No","-","0" "T1154","No","-","0" "T1218.012","No","-","0" "T1572","No","-","0" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml","3" "T1135","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml","3" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml","5" "T1204.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml","5" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml","15" "T1098","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml","15" "T1029","No","-","0" "T1021.004","No","-","0" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml","10" "T1548.002","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml","10" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml","3" "T1556","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml","3" "T1059.007","No","-","0" "T1028","No","-","0" "T1152","No","-","0" "T1596","No","-","0" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml","7" "T1036.003","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml","7" "T1139","No","-","0" "T1051","No","-","0" "T1098.002","No","-","0" "T1591.002","No","-","0" "T1547.011","No","-","0" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1543","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml","10" "T1542.003","No","-","0" "T1036.006","No","-","0" "T1150","No","-","0" "T1176","No","-","0" "T1542","No","-","0" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml","3" "T1218.003","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml","3" "T1071.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml","1" "T1114.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml","1" "T1553.002","No","-","0" "T1552.005","No","-","0" "T1125","No","-","0" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml","2" "T1580","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml","2" "T1563.001","No","-","0" "T1591.004","No","-","0" "T1136.002","No","-","0" "T1583.004","No","-","0" "T1076","No","-","0" "T1021.003","No","-","0" "T1136","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml","10" "T1546.013","No","-","0" "T1598.001","No","-","0" "T1218.004","No","-","0" "T1598.002","No","-","0" "T1584.004","No","-","0" "T1040","No","-","0" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml","6" "T1569","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml","6" "T1053.006","No","-","0" "T1547.002","No","-","0" "T1080","No","-","0" "T1099","No","-","0" "T1596.005","No","-","0" "T1053.003","No","-","0" "T1546.005","No","-","0" "T1564.002","No","-","0" "T1126","No","-","0" "T1098.004","No","-","0" "T1128","No","-","0" "T1590.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","1" "T1116","No","-","0" "T1592.004","No","-","0" "T1499.001","No","-","0" "T1596.004","No","-","0" "T1178","No","-","0" "T1588.003","No","-","0" "T1036.001","No","-","0" "T1064","No","-","0" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml","6" "T1562.007","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml","6" "T1056.001","No","-","0" "T1552.007","No","-","0" "T1495","No","-","0" "T1025","No","-","0" "T1009","No","-","0" "T1049","No","-","0" "T1596.003","No","-","0" "T1590.004","No","-","0" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml","2" "T1114.003","Yes","https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml","2" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1069.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1206","No","-","0" "T1168","No","-","0" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_4104_hunting.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml","16" "T1059.001","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml","16" "T1213.002","No","-","0" "T1543.002","No","-","0" "T1498","No","-","0" "T1111","No","-","0" "T1095","No","-","0" "T1553.004","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml","1" "T1132","No","-","0" "T1559.002","No","-","0" "T1053.002","No","-","0" "T1547.006","No","-","0" "T1131","No","-","0" "T1019","No","-","0" "T1132.001","No","-","0" "T1542.001","No","-","0" "T1001.001","No","-","0" "T1568.001","No","-","0" "T1547.014","No","-","0" "T1565.001","No","-","0" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml","3" "T1531","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml","3" "T1213.001","No","-","0" "T1561.001","No","-","0" "T1187","No","-","0" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml","9" "T1222","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml","9" "T1500","No","-","0" "T1597.001","No","-","0" "T1583.001","No","-","0" "T1566","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml","20" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml","5" "T1087.001","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml","5" "T1608.002","No","-","0" "T1537","Yes","https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml","1" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml","17" "T1078.004","Yes","https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml","17" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml","10" "T1068","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml","10" "T1087.003","No","-","0" "T1145","No","-","0" "T1546.015","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml","1" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","3" "T1595","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml","3" "T1104","No","-","0" "T1097","No","-","0" "T1565.002","No","-","0" "T1560.002","No","-","0" "T1107","No","-","0" "T1090.004","No","-","0" "T1141","No","-","0" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml","8" "T1218.005","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml","8" "T1591","Yes","https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml","1" "T1556.001","No","-","0" "T1035","No","-","0" "T1499.002","No","-","0" "T1092","No","-","0" "T1017","No","-","0" "T1048.001","No","-","0" "T1499","No","-","0" "T1574.010","No","-","0" "T1588.004","No","-","0" "T1611","No","-","0" "T1593.002","No","-","0" "T1583.006","No","-","0" "T1098.001","No","-","0" "T1011.001","No","-","0" "T1556.004","No","-","0" "T1547.008","No","-","0"